
IoTGoat
Deliberately insecure OpenWrt-based firmware for hands-on IoT security training. Features vulnerability challenges mapped to the OWASP IoT Top 10 for…

Deliberately insecure OpenWrt-based firmware for hands-on IoT security training. Features vulnerability challenges mapped to the OWASP IoT Top 10 for…

A Python based web application scanner to gather OSINT and fuzz for OWASP vulnerabilities on a target website.

Burp Suite extension for API security testing with 15 attack types, 108+ payloads, intelligent fuzzing, BOLA/IDOR detection, AI integration, and…

C-based Android static analysis framework for decompilation, secret detection, endpoint discovery, permission analysis, and native library scanning…

MAPS cloud scanner and response parser for Microsoft Defender research.

Hackable HTTP proxy for resiliency testing and simulated network conditions

A command line CWE discovery tool based on OWASP / CAPSEC database of Common Weakness Enumeration.

OWASP Thick Client Application Security Verification Standard

A vulnerable version of Rails that follows the OWASP Top 10

The OWASP Java Encoder is a Java 1.5+ simple-to-use drop-in high-performance encoder class with no dependencies and little baggage. This project will…

OWASP Secure Agent Playbook Project

OWASP Certified Secure-Software Developer

OWASP Smart Contract Security (SCS) Project

Source code for the Binaries of OWASP WrongSecrets

A TypeScript package that provides AI-powered agents for Application Security (AppSec) tasks, built on top of the frontier models.

The OWASP Benchmark GitHub repo has moved to: https://github.com/OWASP-Benchmark/BenchmarkJava